REGISTER REVISED SEPTEMBER 2026

The joiner-mover-leaver process, step by step

ILM Reference editors · Last reviewed September 2026 · 9 minute read

SUMMARYREV. 2026-09

A joiner-mover-leaver (JML) process turns HR events into access changes: create access when someone joins, adjust it when they move, remove it when they leave. It should be triggered by the HR system, not by email, and every step needs an owner and a deadline. The weak point is applications without a connector, which need a ticketed step with the same deadline and a record that it was done.

§ 01

What triggers each JML event?

The HR system of record (Workday, SuccessFactors, BambooHR, Oracle HCM or similar) is the trigger for all three events. Governance platforms read it directly: Okta Lifecycle Management provisions from HR systems such as Workday and SuccessFactors, Lumos monitors the HRIS for role, department, manager and status changes, and C1 connects HR systems so a join, role change, leave or departure triggers a workflow.

§ 02

What happens when someone joins?

  1. HR record created with start date, role, department and manager.
  2. Birthright access assigned by policy (email, HR self-service, collaboration tools).
  3. Role-based access requested or assigned for the specific job.
  4. Disconnected apps: ticket to each app owner with the required role and a due date before start.
  5. Record who created each account and when.
§ 03

What happens when someone moves?

Movers are where access accumulates. The rule is add and remove in the same change: grant the new role's access and remove the old role's access, with a short overlap only where handover requires it and an end date on that overlap. Veza, SailPoint and Lumos all describe removing no-longer-needed access on role change for connected systems. For disconnected apps, a mover ticket must list the access to remove, not only the access to add.

§ 04

What happens when someone leaves?

  1. HR termination date set; leaver workflow starts on that date (or immediately for involuntary exits).
  2. IdP account disabled, which blocks federated sign-on.
  3. Connected app accounts disabled or removed by the IGA.
  4. Disconnected and local accounts removed by ticket to each app owner, with a deadline.
  5. Shared, service and break-glass credentials the person knew are rotated.
  6. Evidence recorded: which accounts, removed by whom, when.
WHY IDP OFFBOARDING IS NOT ENOUGHREV. 2026-09

Disabling the IdP account stops sign-on through SSO. It does not remove a local account inside an application that has its own login page, or an API token issued by the application. Those accounts are the usual source of post-termination access findings.

§ 05

What deadlines should JML steps have?

Set them in policy and measure against them. NIST SP 800-53 Rev. 5 AC-2 leaves the time periods to the organization: it asks that account managers be notified within an organization-defined time period when users are terminated or transferred, and AC-2(3) asks that accounts be disabled within a defined period when they are no longer associated with a user or have been inactive. DORA's technical standard (EU 2024/1774, Article 21) requires withdrawal of access rights upon termination of employment. Whatever deadline you set, apply it to disconnected apps as well.

§ 06

How do you handle apps with no connector?

Four options, often combined: build a connector (in-house or by a systems integrator), use the IGA's file or ticket-based fulfilment (Microsoft documents ServiceNow tickets from Entra entitlement management), use RPA to drive the app's admin screens (Palo Alto Networks' Idira describes this), or use a discovery tool that maps accounts inside the app and feeds the IGA (Orchid Security's approach). See the disconnected applications guide.

FAQ

What does JML stand for?

Joiner, mover, leaver: the three HR events that should change a person's access.

Who owns the JML process?

Usually the IAM team owns the process and tooling, HR owns the trigger data, and application owners own fulfilment for applications the IAM tools cannot reach.

How do you prove a leaver lost access?

Keep the record per account: system, account name, action, actor and timestamp. For disconnected apps, keep the closed ticket and the app owner's confirmation.

Sources

Reviewed Sep 2026

Related

GUIDEREV. 2026-09
TERMREV. 2026-09
COMPARISONREV. 2026-09